CWE-98: CWE-98
Yearly Trend
Top Affected Vendors
All CWE-98 CVEs (608)
This vulnerability allows authenticated low-privileged users to upload restricted file types to IBM Maximo Asset Management by appending a dot to the ...
Jan 24, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 7, 2025The Element Pack Elementor Addons plugin for WordPress has a vulnerability that allows authenticated attackers with contributor-level access or higher...
Aug 12, 2024Nagios XI versions before 2024R1.1.4 contain an authenticated local file inclusion vulnerability in the NagVis integration. Authenticated users can ma...
Oct 30, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 9, 2025This CVE describes a Directory Traversal vulnerability in the Tikit (now Advanced) eMarketing platform that allows remote attackers to read arbitrary ...
Mar 3, 2025This vulnerability in Xinhu Rainrock RockOA 2.7.0 allows attackers to access sensitive system information through the phpinfo() function by manipulati...
Dec 9, 2025CVE-2024-58302 is a local file inclusion vulnerability in FoF Pretty Mail 1.1.2 that allows administrative users to include arbitrary server files in ...
Dec 11, 2025About CWE-98 (CWE-98)
Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.
External reference: View CWE-98 on MITRE CWE →
Monitor CWE-98 Vulnerabilities
Get alerted when new CWE-98 CVEs affect your infrastructure.
Start Monitoring Free